Critical default credential in Kubernetes Image Builder allows SSH root access
ID: 47f053ec-af3d-5321-b1f5-9c748edd41c8
STIX ID: report--47f053ec-af3d-5321-b1f5-9c748edd41c8
Feed Name: The Register (Security)
Threat Score
A critical vulnerability in Kubernetes Image Builder (v0.1.37 and earlier) can leave default credentials in VM images, enabling remote root SSH access; Proxmox-built images are rated CVSS 9.8 (CVE-2024-9486) while other providers have a CVSS 6.3 variant (CVE-2024-9594). Users should upgrade to Image Builder v0.1.38 or later (which randomizes and disables the builder account) or disable the builder account and redeploy affected images to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
